Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2025-71357 picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can… Picklescan 0.0.30+ Fix from $1,9502026-06-21 HIGH 7.8 CVE-2025-71378 picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. … Picklescan 0.0.30+ Fix from $1,9502026-06-21 HIGH 7.8 CVE-2025-71348 picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. At… Picklescan 0.0.28+ Fix from $1,9502026-06-21 MEDIUM 6.5 CVE-2026-56304 picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte file… Picklescan 1.0.1+ Fix from $1,6002026-06-20 HIGH 7.8 CVE-2025-10157 A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsa… Picklescan 0.0.31+ Fix from $1,9502025-09-17 CRITICAL 9.8 CVE-2025-10156 An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker … Picklescan 0.0.31+ Fix from $2,3002025-09-17 HIGH 7.8 CVE-2025-10155 An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacke… Picklescan 0.0.31+ Fix from $1,9502025-09-17 HIGH 7.5 CVE-2025-46417 The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deseria… Picklescan 0.0.25+ Fix from $1,9502025-04-24 CRITICAL 9.8 CVE-2025-1945 picklescan before 0.0.23 fails to detect malicious pickle files inside PyTorch model archives when certain ZIP file flag bits are modified. By flippi… Picklescan 0.0.23+ Fix from $2,3002025-03-10 MEDIUM 6.5 CVE-2025-1944 picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to extract and scan PyTorch model… Picklescan 0.0.23+ Fix from $1,6002025-03-10 CRITICAL 9.8 CVE-2025-1889 picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious … Picklescan 0.0.22+ Fix from $2,3002025-03-03 CRITICAL 9.8 CVE-2025-1716 picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious … Picklescan 0.0.22+ Fix from $2,3002025-02-26